Skip to content

Evidence request lists

NIST SP 800-66

Evidence request list. 8 controls, 8 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

Business Associate Agreements

NISTSP66-4
Business Associate Agreements (BAAs) and Third-Party ePHI Governance

Manage Business Associate relationships per HIPAA Security Rule 45 CFR 164.308(b) and HIPAA Privacy Rule 45 CFR 164.502(e). Obtain satisfactory assurances per a written contract or other arrangement (a Business Associate Agreement - BAA) that the business associate will appropriately safeguard ePHI per 45 CFR 164.314(a). The BAA must require the business associate to (a) not use or further disclose ePHI other than as permitted or required by the contract or law, (b) use appropriate safeguards to prevent use or disclosure not provided for by the contract, (c) report any use or disclosure not provided for by the contract of which the business associate becomes aware, (d) ensure any subcontractor that creates + receives + maintains + transmits ePHI on behalf of the business associate agrees to the same restrictions and conditions, (e) make ePHI available to the covered entity for access + a

Artefacts an auditor will ask for
  • BAA inventory with all business associates touching ePHI
  • executed BAAs with required clauses per 45 CFR 164.314 + 164.504(e)
  • BA risk assessment + ongoing oversight evidence
  • subcontractor flow-down verification evidence
Where this commonly fails
  • BAA inventory incomplete missing cloud sub-processors
  • subcontractor flow-down not verified
  • BA breach notification clock not aligned with covered entity obligations

Incident + Contingency + Evaluation

NISTSP66-3
Security Incident Procedures, Contingency Plan, and Evaluation

Implement HIPAA Security Rule Administrative Safeguards for incident response + contingency + evaluation. Security Incident Procedures per 45 CFR 164.308(a)(6): identify and respond to suspected or known security incidents + mitigate harmful effects + document incidents and outcomes. Contingency Plan per 45 CFR 164.308(a)(7): Data Backup Plan (Required) + Disaster Recovery Plan (Required) + Emergency Mode Operation Plan (Required) + Testing and Revision Procedures (Addressable) + Applications and Data Criticality Analysis (Addressable). Evaluation per 45 CFR 164.308(a)(8): perform periodic technical and non-technical evaluation initially based on the standards and subsequently in response to environmental or operational changes affecting the security of ePHI. Apply NIST SP 800-61 IR methodology and NIST SP 800-34 contingency planning methodology + integrate with HIPAA Breach Notification

Artefacts an auditor will ask for
  • security incident procedures + incident log + breach analysis records
  • Contingency Plan covering Data Backup + DR + Emergency Mode + Testing + Criticality Analysis
  • annual tabletop and biennial technical recovery test evidence + lessons learned + plan updates
  • evaluation reports (technical and non-technical) per cycle
Where this commonly fails
  • contingency plan exists but never tested
  • evaluation skipped or limited to a subset of safeguards
  • incident procedures not integrated with breach notification clock

Integration with NIST RMF, CSF, OCR Enforcement

NISTSP66-8
Integration with NIST RMF, Cybersecurity Framework, and OCR Enforcement Posture

Operate HIPAA Security Rule compliance using NIST SP 800-66 Rev 2 as the bridge to broader NIST cybersecurity guidance per Chapter 5 of SP 800-66 Rev 2. Map HIPAA Security Rule standards to NIST Cybersecurity Framework 2.0 functions + categories + subcategories using the crosswalk in SP 800-66 Rev 2 Appendix F. Map HIPAA Security Rule to NIST SP 800-53 Rev 5 controls using the crosswalk in SP 800-66 Rev 2 Appendix G for organisations operating under NIST RMF (SP 800-37 Rev 2). Integrate HIPAA Security Rule risk analysis (NISTSP66-1) with NIST SP 800-30 Rev 1 + NIST SP 800-39 enterprise risk management. Integrate HIPAA Security Rule incident procedures (NISTSP66-3) with NIST SP 800-61 Rev 2 IR methodology. Integrate HIPAA Security Rule contingency planning (NISTSP66-3) with NIST SP 800-34 contingency planning + NIST SP 800-160 vol 2 cyber resilience. Maintain readiness for OCR Audit Progr

Artefacts an auditor will ask for
  • mapping evidence to NIST CSF 2.0 + NIST SP 800-53 Rev 5 per SP 800-66 Rev 2 Appendices F + G
  • RMF Authorize step evidence where applicable
  • OCR audit readiness package + ransomware preparedness + cloud ePHI governance + BAA enforcement evidence
  • alignment with NIST SP 800-30 risk analysis + SP 800-61 IR + SP 800-34 contingency + SP 800-160 vol 2 resilience
Where this commonly fails
  • HIPAA Security Rule maintained in isolation from broader NIST framework
  • no documented OCR audit readiness
  • ransomware preparedness limited despite OCR enforcement focus

Physical Safeguards

NISTSP66-5
Physical Safeguards: Facility Access, Workstation Use and Security, Device and Media Controls

Implement HIPAA Security Rule Physical Safeguards per 45 CFR 164.310. Facility Access Controls per 45 CFR 164.310(a): Contingency Operations + Facility Security Plan + Access Control and Validation Procedures + Maintenance Records (all Addressable). Workstation Use per 45 CFR 164.310(b): specify proper functions to be performed + manner of performance + physical attributes of the surroundings of a specific workstation or class of workstation that can access ePHI. Workstation Security per 45 CFR 164.310(c): implement physical safeguards for all workstations that access ePHI to restrict access to authorized users. Device and Media Controls per 45 CFR 164.310(d): Disposal (Required) + Media Re-use (Required) + Accountability (Addressable) + Data Backup and Storage (Addressable) covering hardware and electronic media that contain ePHI + procedures for receipt and removal of hardware and elec

Artefacts an auditor will ask for
  • facility access procedures + access logs + maintenance records
  • workstation use policy + workstation security configuration
  • device and media inventory + disposal records per NIST SP 800-88 + media re-use sanitisation records
Where this commonly fails
  • mobile device inventory incomplete
  • disposal not documented
  • BYOD ePHI without containerisation or remote wipe

Policies, Procedures, Documentation

NISTSP66-7
Policies, Procedures, Documentation, and Organisational Requirements

Maintain HIPAA Security Rule Policies + Procedures + Documentation per 45 CFR 164.316 and Organisational Requirements per 45 CFR 164.314. Policies and Procedures per 45 CFR 164.316(a): implement reasonable and appropriate policies and procedures to comply with the standards + implementation specifications + and other requirements of the Security Rule. Documentation per 45 CFR 164.316(b)(1): maintain the policies and procedures in written (which may be electronic) form + maintain a written or electronic record of any action + activity + or assessment required by the Security Rule. Documentation Retention per 45 CFR 164.316(b)(2)(i): retain documentation for 6 years from the date of its creation or the date when it last was in effect whichever is later. Documentation Availability per 45 CFR 164.316(b)(2)(ii): make documentation available to those persons responsible for implementing the pr

Artefacts an auditor will ask for
  • policies + procedures library covering all Security Rule standards
  • documentation retention evidence (6 years from last effective date)
  • documentation availability + access controls for implementers
  • documentation update cycle + change log
Where this commonly fails
  • policies retired without retention for 6 years going forward
  • documentation not available to implementers
  • no periodic review or update cycle

Security Management Process - Risk Analysis and Risk Management

NISTSP66-1
Security Management Process: Risk Analysis and Risk Management for ePHI

Implement the HIPAA Security Rule Security Management Process Administrative Safeguard at 45 CFR 164.308(a)(1) per NIST SP 800-66 Rev 2. Conduct an accurate and thorough Risk Analysis per 45 CFR 164.308(a)(1)(ii)(A) of the potential risks and vulnerabilities to the confidentiality + integrity + availability of electronic protected health information (ePHI) held by the covered entity or business associate using NIST SP 800-30 Rev 1 risk assessment methodology. Implement Risk Management per 45 CFR 164.308(a)(1)(ii)(B) sufficient to reduce risks and vulnerabilities to a reasonable and appropriate level to comply with 45 CFR 164.306(a). Apply Sanction Policy per 45 CFR 164.308(a)(1)(ii)(C) for workforce members who fail to comply with security policies and procedures. Conduct Information System Activity Review per 45 CFR 164.308(a)(1)(ii)(D) to regularly review records of information system

Artefacts an auditor will ask for
  • Risk Analysis document per SP 800-30 Rev 1 methodology covering ePHI confidentiality + integrity + availability
  • Risk Management Plan reducing risks to reasonable and appropriate level
  • Sanction Policy and disciplinary action records for violations
  • Information System Activity Review procedures + sample log reviews
Where this commonly fails
  • risk analysis missing or scoped only to a subset of ePHI repositories
  • risk treatment plan absent so risks identified but not addressed
  • sanction policy not consistently applied
  • activity review process documented but no evidence of execution

Technical Safeguards

NISTSP66-6
Technical Safeguards: Access Control, Audit Controls, Integrity, Person Authentication

Implement HIPAA Security Rule Technical Safeguards per 45 CFR 164.312 covering technical access + audit + integrity + authentication. Access Control per 45 CFR 164.312(a)(1): Unique User Identification (Required) + Emergency Access Procedure (Required) + Automatic Logoff (Addressable) + Encryption and Decryption (Addressable) at rest. Audit Controls per 45 CFR 164.312(b): implement hardware + software + procedural mechanisms that record and examine activity in information systems that contain or use ePHI. Integrity per 45 CFR 164.312(c)(1): implement policies and procedures to protect ePHI from improper alteration or destruction including Mechanism to Authenticate ePHI (Addressable). Person or Entity Authentication per 45 CFR 164.312(d): implement procedures to verify that a person or entity seeking access to ePHI is the one claimed. Transmission Security per 45 CFR 164.312(e)(1): Integr

Artefacts an auditor will ask for
  • unique user IDs + emergency access procedure + automatic logoff + encryption-at-rest evidence
  • audit log configuration + retention + review evidence
  • integrity controls + ePHI authentication mechanism evidence
  • person/entity authentication evidence (MFA where applicable)
  • transmission encryption (TLS) evidence + decryption keys management
Where this commonly fails
  • encryption not implemented without documented risk-based rationale (Addressable status misinterpreted)
  • audit logs collected but never reviewed
  • shared accounts violating Unique User Identification

Workforce Security + Access + Training

NISTSP66-2
Workforce Security, Information Access Management, and Awareness Training

Implement HIPAA Security Rule Administrative Safeguards covering workforce + access + training. Workforce Security per 45 CFR 164.308(a)(3): Authorization and/or Supervision of workforce members + Workforce Clearance Procedures + Termination Procedures ensuring access revocation when employment ends or roles change. Information Access Management per 45 CFR 164.308(a)(4): Isolating Health Care Clearinghouse Functions + Access Authorization (procedures for granting access to ePHI through workstation + transaction + program + process) + Access Establishment and Modification (procedures to establish + document + review + modify access rights). Security Awareness and Training per 45 CFR 164.308(a)(5): Security Reminders + Protection from Malicious Software + Log-In Monitoring + Password Management. Apply minimum necessary principle per 45 CFR 164.502(b) when establishing access. Maintain work

Artefacts an auditor will ask for
  • workforce roster + authorisation records + clearance evidence + termination workflow with maximum hours SLA
  • access establishment + modification + review records
  • security awareness training records + phishing simulation evidence + minimum necessary policy
Where this commonly fails
  • termination not propagated to all ePHI systems within SLA
  • stale access of former workforce members
  • training general not HIPAA-specific or not refreshed annually
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the NIST SP 800-66 framework page.